Data Controller

MPF App Oy
Laajalahdentie 16, 00330 Helsinki, Finland
Business ID (Y-tunnus) 3541877-3 · VAT FI35418773 · Domicile: Helsinki · Finnish Trade Register
info@ciaerampf.com

Ciaera is a registered auxiliary business name of MPF App Oy. The app is called Ciaera; the company you are contracting with, and the one answerable for your data, is MPF App Oy.

Data protection contact. At our current scale we are not required to appoint a Data Protection Officer under Art. 37 GDPR, so we have not appointed one. Data protection questions and rights requests go to the controller directly, at info@ciaerampf.com. If our processing grows to the point where Art. 37 applies, we will appoint a DPO and say so here.

1 Who we are

Ciaera is a workplace well-being app made by MPF App Oy, a company registered in Finland. Employees use it to check in on how they are doing and to talk things through privately with an AI companion. HR leaders get an anonymous, aggregated read on how the team is doing — and nothing else.

MPF App Oy is the data controller for the personal data described here. If you want to exercise a right, or you just want to know what we hold about you, write to info@ciaerampf.com.

2 What this policy covers

This policy covers the Ciaera iOS and Android apps, the HR dashboard at hr.ciaerampf.com, this website at ciaerampf.com, and the backend that serves all three.

It does not cover what your employer does with its own HR records, its own systems, or anything you tell a manager outside Ciaera. Your employer is a separate data controller for all of that — see Section 8.

3 What we collect, and why

3.1 Account data

When your account is created we store your email address, your password as a one-way bcrypt hash (we cannot read it, and we cannot recover it for you), your role — employee or HR leader — and which company account you belong to. We record the time you gave consent and the version of this policy you agreed to.

Alongside that, the app stores a few small settings so it behaves correctly: your interface language, your time zone (sent by the app so that "this morning" means your morning and not UTC), the time of your last sign-in, and — if your company uses departments — which department you are in.

An email address is a contractual requirement: without one we cannot create an account or provide the service. Everything in 3.2 to 3.6 rests on your consent instead, and you can withdraw it at any time.

3.2 Mood check-ins

When you log a mood we store the emoji and label you picked and the time you picked it. Encrypted at rest under a key derived for your account alone.

3.3 Chat conversations

We store the messages you send and the replies you get back, encrypted at rest under your account's key. To produce a reply, the message is sent to Anthropic's Claude — Section 7 sets out what Anthropic may and may not do with it.

3.4 AI memory notes and summaries

So that the companion picks up where you left off instead of meeting you fresh every time, Ciaera keeps a short encrypted note of recurring themes and context from your past conversations, plus brief per-day and per-week summaries used to give the AI a sense of your timeline. None of it is visible to your HR leader or your employer, ever. You can wipe the note yourself by telling Ciaera to forget everything about you, in any language it speaks.

3.5 Journal entries

If you save a conversation to your journal, we store a reference to that session and the mood you had at the time. Encrypted at rest, and private to you.

3.6 Anonymous feedback

Feedback you send through the app is stored against your company, never against you. The text carries no user ID and no timestamp that could place it. We separately record the bare fact that you have submitted at some point, with no link to any text, purely so the dashboard can count distinct contributors and enforce the five-person minimum. Deleting your account or withdrawing consent removes that participation record; the anonymous text stays, because by then nothing connects it to you.

3.7 Technical, security and abuse-prevention data

Some data exists only to keep the service standing up:

3.8 Records of rights requests

When you exercise a right — withdrawing consent, deleting your account — we log that it happened, when, and who asked for it. GDPR Art. 5(2) requires us to be able to demonstrate that we honoured it. The log holds no well-being data.

We do not collect anything else. There are no advertising SDKs, no cross-app tracking, no third-party analytics in the mobile apps, and no data brokers anywhere in the picture.

4 The one safety check we run on messages

Every account has a daily and monthly ceiling on AI usage, to stop one runaway session draining the company's budget. We were not willing to let a cost control cut someone off mid-sentence on the worst day of their year.

So when — and only when — a message is about to be blocked by one of those ceilings, Ciaera checks whether it reads like an acute crisis. First with a fixed word list covering all eight supported languages, and if that finds nothing, with a single yes/no classification by Claude Haiku. If either says yes, the message goes through anyway. If the check itself fails for any reason, the message goes through anyway.

When that bypass fires, an internal alert is written so we can see the ceilings are being used as intended. The alert contains your user ID, your company ID and the time. It does not contain your message, any part of it, or what it was about. Your employer never sees these alerts — they go to us, not to them. They are deleted when you delete your account or withdraw consent.

To be plain about it

This is not monitoring, and no human reads your chats. Nobody is alerted to come and find you, and no one at your company is told anything. The check runs on a single message, in memory, at the moment a budget limit would otherwise have silenced it.

Ciaera is not an emergency service and cannot get help to you. If you are in danger right now, call 112 anywhere in the EU. In Finland, MIELI Mental Health Finland runs a national crisis line — mieli.fi.

5 Health-related data

Mood entries and the content of your conversations can reveal something about your mental health. Under Art. 9 GDPR that makes them special category data, which carries the strictest protection in the regulation, and we treat them accordingly.

We process them on one basis only: your explicit consent under Art. 9(2)(a), given on a dedicated screen before your account exists. You can withdraw it at any time, from inside the app. Withdrawing does not make the processing before it unlawful — it stops it going forward, and erases what was collected. Section 10 explains exactly what happens.

6 What your HR leader can and cannot see

Your HR leader cannot see:

Your HR leader can see:

The five-person floor is enforced in the backend, on every query, not in the interface. There is no setting, no admin override and no support request that turns it off, and there is no screen anywhere in the product — including our own admin console — that displays one person's mood history or chat.

7 Who else touches your data

These are every third party our production systems reach. All of them are bound by data processing agreements with us. If we add one, we will list it here and give notice before it starts processing, as described in Section 14.

Sub-processor What it does Location Transfer safeguard
Anthropic PBCanthropic.com Generates the AI replies, the private memory notes and summaries, and the aggregated HR insights. Receives your chat messages. United States Standard Contractual Clauses — Art. 46 GDPR
Railway Corp.railway.com Runs the backend, the PostgreSQL database where everything is stored, and the Redis cache used for rate limits and short-lived locks. EU — Amsterdam, Netherlands Data stays in the EU/EEA
Resend, Inc.resend.com Delivers transactional email: address verification, password resets, weekly prompts, security notices. United States Standard Contractual Clauses — Art. 46 GDPR
Functional Software, Inc. (Sentry)sentry.io Collects backend error reports so faults get fixed. Configured to send no request bodies, headers or user identifiers. United States Standard Contractual Clauses — Art. 46 GDPR
Vercel Inc.vercel.com Hosts this marketing site and the HR dashboard, including cookieless page-view analytics. United States Standard Contractual Clauses — Art. 46 GDPR
On the AI, specifically

Your messages are sent to Anthropic over the commercial API. Under Anthropic's commercial terms, inputs and outputs sent through that API are not used to train its models. Anthropic retains them briefly for its own trust-and-safety purposes and then deletes them; it does not receive your name or email, only the message text and a company API key.

Each company brings its own Anthropic key, so one customer's conversations are never mixed into another's usage.

Transfers outside the EU

Anthropic, Resend, Sentry and Vercel are US companies. Those transfers rely on Standard Contractual Clauses approved by the European Commission under Art. 46 GDPR, and nothing else. We do not rely on your consent as a transfer mechanism, so withdrawing consent never leaves a transfer un-covered.

Everything at rest — the database, every mood entry, every message — is in Amsterdam.

We do not sell data, we do not share it for anyone's marketing, and we do not give your employer anything beyond the aggregates in Section 6. If a court or authority ever compelled disclosure, we would tell you unless the law forbade it.

8 Your employer's role, and its limits

Your employer buys Ciaera and decides that its staff may use it. For its own HR and employment records it is a data controller in its own right, under its own privacy notice, and this policy does not reach any of that.

For everything inside Ciaera, MPF App Oy is the controller. That distinction is the whole point: your employer cannot instruct us to hand over your entries, cannot ask us to identify who said what, and cannot buy an upgrade that unlocks it. There is no version of Ciaera in which that view exists.

Where the paperwork stands, honestly

Ciaera is in early deployment, and we have not yet put a signed data processing agreement in place with every customer company. We offer one on request and will sign it before any customer needs it. We would rather say that plainly here than imply a contract that is not yet on file.

Nothing about that changes what a customer can see. The five-person floor and the separation described in Section 6 are enforced by the software itself, not by a clause.

9 How long we keep things

A sweep runs every night at 02:00 UTC and deletes anything past its window. This table is what that job actually does.

DataKept for
Account dataUntil you delete your account. An employee account with no mood entry and no conversation for 12 months is also deleted automatically, along with everything in it.
Mood check-ins12 months from the entry
Conversations and messages12 months from the session
Journal entries12 months from saving
AI memory notesCleared after 180 days with no conversation, or whenever you ask Ciaera to forget you, or on account deletion — whichever comes first
Per-day AI summaries30 days
Per-week AI summaries13 months
Anonymous feedback12 months from submission
Cached HR overviews13 months
AI usage counters (no content)12 months
Password reset tokensStored hashed, single use, valid one hour; the spent record is purged after 7 days
Rate-limiting data and HR session fingerprintsMinutes to 25 hours, in cache only
Error diagnostics at SentryUp to 90 days, then deleted by Sentry
Internal alerts (usage ceilings, crisis bypass, session sharing)90 days once read, 12 months if never read — and immediately on account deletion or consent withdrawal
Demo requests from this website90 days
Records of rights requests3 years, then purged

You never have to wait for any of it. Deletion from inside the app is immediate — see Section 10.

10 Your rights, and how to use them

Two of these you can exercise yourself, in about ten seconds, without asking us. For the rest, write to info@ciaerampf.com and we will answer within 30 days.

Access — Art. 15

Ask for a copy of everything we hold about you. Or take it yourself: the export below is the same data.

Portability — Art. 20

In the app: Settings → Privacy & Data → Export my data. Machine-readable JSON, generated on the spot, yours to keep or move.

Erasure — Art. 17

In the app: Settings → Danger Zone → Delete account. Immediate and irreversible. An HR leader who is the last one left in an active company has to hand over ownership first, or ask us to close the company account — otherwise the company would be stranded with no administrator.

Withdraw consent — Art. 7(3)

In the app: Settings → Privacy & Data → Withdraw consent. Detailed below — it erases rather than pauses.

Rectification — Art. 16

Change your email and password in the app. For anything else, write to us and we will correct it.

Restriction — Art. 18

Ask us to freeze processing rather than erase it, in the circumstances the article allows.

Object — Art. 21

Object to anything we do on legitimate-interest grounds — the security and abuse-prevention data in 3.7. We stop unless we can show compelling grounds that override yours.

No automated decisions — Art. 22

Nothing here makes a decision about you with legal or similarly significant effect. The AI writes suggestions from aggregates, for a human to read and judge.

What withdrawing consent actually does

It is stronger than the name suggests, and worth knowing before you tap it. The moment you confirm:

What remains for 30 days is an empty account shell — your email address and login, holding no well-being data whatsoever. That window exists so you can come back and re-consent without starting over. If you do not, the sweep removes the shell: employee accounts are deleted outright, and HR accounts are anonymised instead, because a company's records would break if its administrator row simply vanished.

Deleting your account instead of withdrawing consent skips the 30-day window entirely and removes everything at once.

If we get it wrong

Tell us first if you are willing — it is usually faster. But you never have to, and you can go straight to the Finnish supervisory authority at any time. Details in Section 15.

11 How it is protected

Mood labels, chat messages, journal entries and AI memory notes are encrypted at rest with AES-256-GCM, under keys derived per user from a server-side secret. The keys themselves are never stored anywhere — they are derived on demand and discarded. Someone walking off with a full database dump gets ciphertext.

In transit, everything runs over TLS 1.2 or better. Both mobile apps additionally pin the certificate authority's root keys, so a forged certificate from a compromised or coerced CA does not get a connection.

Passwords are hashed with bcrypt at cost factor 12. Sessions use short-lived JWTs with a revocation counter, so changing a password, changing a role or withdrawing consent invalidates every token already issued. Access to our admin console requires a second factor (TOTP) on every login. Row-level security in the database keeps one company's rows unreachable from another company's session.

If a breach happens that is likely to put your rights at risk, we notify the Finnish supervisory authority within 72 hours of finding out (Art. 33), and if the risk to you personally is high, we tell you directly and without delay (Art. 34). We would rather over-notify than manage the news.

12 Cookies, storage and this website

The mobile apps

No cookies, no advertising SDKs, no analytics, no cross-app tracking. The apps talk to our API and to nothing else.

This website

No cookies at all. We use Vercel Web Analytics, which is cookieless: it counts page views in aggregate, sets nothing on your device, does not fingerprint your browser and cannot follow you to another site. One entry in your browser's local storage remembers that you have already dismissed the storage notice, so it does not reappear on every visit. That is the entire list.

Both typefaces on this site — Fraunces and Inter — are served from our own domain. Your browser makes no request to Google Fonts and no IP address of yours reaches a font provider.

The demo form

If you ask for a demo, your email address is used to send you one confirmation and to reach our own inbox so a human can reply. We do not store the address in our database. What is stored is a one-way SHA-256 hash of it, alongside the time you consented, purely so we can count and de-duplicate requests — and that record is deleted after 90 days. You are not added to a mailing list, and there is nothing to unsubscribe from.

The HR dashboard

hr.ciaerampf.com sets no cookies either. It keeps your session token in sessionStorage, which your browser clears the moment the tab closes, and caches your dashboard in localStorage in encrypted form with the key held in sessionStorage — so the cache is unreadable once the tab is gone. Your language choice and whether you have seen the product tour are also stored locally. All of it is strictly necessary to run the dashboard you asked for, and none of it tracks you.

13 Children

Ciaera is a workplace tool and is not meant for anyone under 16. We do not knowingly collect data from minors. If you believe a minor has an account, write to info@ciaerampf.com and we will delete it.

14 When this policy changes

Every revision is dated and summarised at the bottom of this page, so you can see what moved and when rather than having to diff two versions of a legal document.

If a change would widen what we do with data you consented to, we will ask you to actively agree before you carry on using Ciaera. The consent version at the top of this page is the mechanism: raise it, and the app stops and asks. We will not treat carrying on using the app as agreement.

For corrections, clarifications and new sub-processors — changes that do not widen anything — we update this page, log the revision below, and give notice before a new sub-processor starts. You can object to any of it at info@ciaerampf.com.

15 Supervisory authority

If you think we are handling your data unlawfully, you can complain to the Finnish data protection authority. You do not need our permission and you do not need to contact us first.

Office of the Data Protection Ombudsman
Tietosuojavaltuutetun toimisto
PO Box 800, FI-00531 Helsinki, Finland
tietosuoja@om.fi · tietosuoja.fi

Revision history

Consent version 1.1 is the version of this policy you agreed to in the app. Revisions that do not widen processing keep the same consent version — see Section 14.

11 August 2026Consent version 1.1
A correction pass after auditing this page line by line against the running system. Nothing here widens what we do with your data; several items narrow it.
  • Corrected the retention of AI memory notes: cleared after 180 days without a conversation, not 24 months as previously stated.
  • Disclosed that dormant employee accounts are deleted automatically after 12 months of no activity.
  • Added Sentry to the sub-processor list, and stated that Railway also runs our Redis cache.
  • Added Section 4, describing the crisis check that lets a message past a usage ceiling, and exactly what the resulting internal alert does and does not contain.
  • Named the technical data we had only described in general terms: IP addresses, HR session fingerprints, usage counters, accountability records.
  • Stated what Anthropic may do with chat messages, including that they are not used to train models.
  • Corrected the in-app paths for export, deletion and consent withdrawal, which named a screen that does not exist.
  • Described what withdrawing consent actually does, including the 30-day re-consent window.
  • Replaced the claim that a data processing agreement is in place with every customer with an accurate statement of where that stands.
  • Corrected the demo form section: the email address is not stored in our database, only a hash of it.
  • Added the company's Business ID, VAT number and register details, and disclosed the HR dashboard's browser storage.
3 May 2026Consent version 1.1
Clarified that the website's data-collection statement covers the email address only, and listed the self-hosted typefaces.
20 April 2026Consent version 1.0
First published.